Definition
Muse is Meta's personal AI agent. It retains context across conversations, works through tasks using connected applications and a browser, and continues scheduled or event-driven work while its user is away. A dedicated cloud computer holds its workspace and agent state.
Muse Spark supplies model capabilities. The Muse product adds the harness, memory, tools, permissions, and interfaces that let those capabilities operate on a person's behalf.
Origin and attribution
Meta introduced Muse on September 8, 2026. Its launch announcement credits the company. Tarek Sheasha, a software engineer and vice president at Meta Superintelligence Labs, published the technical safety account. Mona Sarantakos and Christine Awad explained the product's design. These accounts document team responsibilities; they do not identify a sole inventor.
Meta's launch headline calls Muse the first personal agent built for everyone. That is a vendor positioning claim. The product introduction alone does not establish historical priority over other personal-agent systems.
Operation, memory, and permissions
Users can maintain a main conversation and side chats, give Muse multiple tasks, and inspect its activity. The design account describes readable, editable memory files and controls for changing how proactively it contacts the user.
Meta's launch architecture places the agent inside a runtime cell. A separate host-side Sentinel authorizes connector actions and network egress, while a credential service keeps real tokens outside the agent's context. Approval grants have a defined destination, purpose, and duration. Changing an instruction file does not grant the agent authority to override Sentinel.
Limits and privacy boundaries
Persistent context can carry mistaken observations into later tasks. Inspecting memory and activity helps identify errors, but an attractive plan or completed-looking artifact still needs evidence that the requested work succeeded.
The launch safety account explicitly acknowledges prompt injection and other mistakes. Its Secure VM restricts Meta personnel through operational policies while allowing access needed to run the service. Confidential VM, intended to prevent provider access cryptographically, is described as a separate planned capability with a different privacy promise.
Meta also describes using sanitized interaction trajectories for model training with a user opt-out. Excluding conversations from its advertising systems does not exclude them from training or prevent all provider access.
Distinguish it from nearby terms
- A personal agent is the general operating pattern. Muse is one named product.
- Muse models include Spark and other model families. Model access alone does not provide the Muse agent's cloud computer or account permissions.
- Agent memory retains information for later decisions. A user-editable memory file can change context; permission enforcement remains a separate system.
- Dots and Grok Bot are other persistent agent products. Their memory, execution, and approval boundaries require their own documentation.
Check your understanding
A Muse remembers a preference correctly but attempts to send a document to the wrong person. Which records would establish the intended recipient, the permission actually granted, and whether the external action happened?